Re: [IPsec] SHA-1 signatures in IKEv2

2016-11-27 Thread Paul Wouters
On Wed, 23 Nov 2016, John Mattsson wrote: One question, currently SHA-1 signature are not only allowed by RFC7296, but even "SHOULD use as default”. 4307bis does not change this. Shouldn’t something be done about this. Right now (and even with 4307bis): From Section 4 of the bis document:

[IPsec] SHA-1 signatures in IKEv2

2016-11-23 Thread John Mattsson
One question, currently SHA-1 signature are not only allowed by RFC7296, but even "SHOULD use as default”. 4307bis does not change this. Shouldn’t something be done about this. Right now (and even with 4307bis): RSASSA-PKCS1-v1.5 with SHA-1 is MUST support and everything else (PSS+SHA-2, ECSDA+SHA